11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2008-0964
Software Genérico Windows
N/A
UNKNOWN
EPSS
28.6%
2008 1 PoC

Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.

CVE-2008-2595
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
13.5%
2008 1 PoC

Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a denial of service (crash) via a malformed LDAP request that triggers a NULL pointer dereference.

CVE-2008-4078
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.7%
2008 1 PoC

SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVE-2008-4834
Software Genérico Windows
N/A
UNKNOWN
EPSS
73.9%
2008 1 PoC

Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."

CVE-2008-4077
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2008 1 PoC

The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large Content-Length.

CVE-2008-5821
Software Genérico Windows
N/A
UNKNOWN
EPSS
13.7%
2008 1 PoC

Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory consumption and browser crash) via a long ALINK attribute in a BODY element in an HTML document.

CVE-2008-1105
Software Genérico Windows
N/A
UNKNOWN
EPSS
85.7%
2008 2 PoCs

Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.

CVE-2007-6405
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
9.4%
2007 1 PoC

Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character, (2) '.' character, (3) %2e sequence (hex-encoded dot), or (4) hex-encoded character greater than 0x7f. NOTE: the %20 vector is already covered by CVE-2007-3407.

CVE-2014-7151
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the NEX-Forms Lite plugin 2.1.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the form_fields parameter in a (1) do_edit or (2) do_insert action to wp-admin/admin-ajax.php.

CVE-2015-6103
Software Genérico Windows
N/A
UNKNOWN
EPSS
54.5%
2015 2 PoCs

The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows Graphics Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-6104.

CVE-2008-1447
Software Genérico Windows
N/A
UNKNOWN
EPSS
86.7%
2008 7 PoCs

The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."

CVE-2008-0508
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2008 2 PoCs

Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the oldstructure (aka dean_pm_config[oldstructure]) configuration setting as administrators via the old_struct parameter in a deans_permalinks_migration.php action to wp-admin/options-general.php, as demonstrated by placing an XSS sequence in this setting.

CVE-2008-2161
Software Genérico Windows
N/A
UNKNOWN
EPSS
78.9%
2008 1 PoC

Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet. NOTE: some of these details are obtained from third party information.

CVE-2008-6386
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.6%
2008 1 PoC

Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVE-2008-5439
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.5%
2008 1 PoC

Unspecified vulnerability in the SQL*Plus Windows GUI component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality via unknown vectors.

CVE-2008-0682
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2008 1 PoC

SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2008-0429
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2008 2 PoCs

SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum_catview action.

CVE-2008-4261
Software Genérico Windows
N/A
UNKNOWN
EPSS
64.4%
2008 2 PoCs

Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."

CVE-2015-5471
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
54.0%
2015 2 PoCs

Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter.

CVE-2008-3285
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.5%
2008 1 PoC

The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell metacharacters.